CVE-2026-92756

Source
https://cve.org/CVERecord?id=CVE-2026-92756
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92756.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-92756
Published
2026-09-17T19:04:51Z
Modified
2026-09-26T11:47:44Z
Severity
  • 6.8 (Medium) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N CVSS Calculator
Summary
Combining encryption settings may disable encryption
Details

Applications built on MongoDB Entity Framework Core Provider which combine independent encryption settings and this provider's encryption settings may silently lose TLS and schema-map settings leading to protected fields being stored unencrypted in the database.

Database specific
{
    "cna_assigner": "mongodb",
    "cwe_ids": [
        "CWE-311"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92756.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "8.0.0"
                },
                {
                    "fixed": "8.4.3"
                },
                {
                    "introduced": "9.0.0"
                },
                {
                    "fixed": "9.1.3"
                },
                {
                    "introduced": "10.0.0"
                },
                {
                    "fixed": "10.0.3"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/mongodb/mongo-efcore-provider

Affected ranges

Type
GIT
Repo
https://github.com/mongodb/mongo-efcore-provider
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:mongodb:entity_framework_core_provider:*:*:*:*:*:.net:*:*",
    "extracted_events": [
        {
            "introduced": "8.0.0"
        },
        {
            "fixed": "8.4.3"
        },
        {
            "introduced": "9.0.0"
        },
        {
            "fixed": "9.1.3"
        },
        {
            "introduced": "10.0.0"
        },
        {
            "fixed": "10.0.3"
        }
    ],
    "source": "CPE_RANGE"
}

Affected versions

v10.*
v10.0.0
v10.0.1
v10.0.2
v8.*
v8.4.0
v8.4.1
v8.4.2
v9.*
v9.1.1
v9.1.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92756.json"